HarborGuard / CVE
Back to search
HIGHCVE-2026-40459Published Modified CNA CERT-PL

CVE-2026-40459: LDAP Injection in PAC4J

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
4.5.10
Affected Products
1

Fix available

4.5.105.7.106.4.1
Affected packages
  • PAC4J / PAC4J
    < 4.5.10 (from 4.0) · < 5.7.10 (from 5.0) · < 6.4.1 (from 6.0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N